
A fresh exploit drained roughly $7.3 million to $7.5 million from the same Verus bridge contract hit in May, with researchers saying the bridge still failed to verify that Ethereum payouts were economically backed on the Verus side.
Verus’s Ethereum bridge was hit by another exploit on July 23, with blockchain security researchers estimating losses at roughly $7.3 million to $7.5 million in ETH and tokens drained from the same contract targeted in May. Researchers said the attacker used a maliciously crafted import from the Verus side to trigger Ethereum-side reserve payouts that were backed by valid notary signatures, state roots and Merkle proofs, but not by matching locked or exported assets on the source chain. Assets taken included Ether, tBTC, MKR, USDC, Tether, EURC and scrvUSD, while the bridge also interacted with a Sky collateral position to mint about 220,357 DAI to satisfy the fraudulent request. Backward Labs said the root cause was an authorization bypass and protocol-state assumption issue, and published a proof-of-concept describing a broken invariant in the bridge lifecycle checks. The firm said the same root cause had remained exploitable for 66 days. The incident was the second breach of the same contract and vulnerability in about two months after the May 17 attack that stole about $11.6 million, bringing cumulative losses to about $19.1 million. The repeat exploit underscores a familiar DeFi bridge risk: cryptographic proofs can validate correctly even when business-logic checks fail to confirm the payout is economically backed.